stix:DiscoveryMethodCodeSimpleType

Code Value Definition
agent-disclosureThe incident was disclosed by the threat agent (e.g., public brag, private blackmail)
antivirusThe incident was discovered by an antivirus system
auditThe incident was discovered during an external security audit or scan
customerThe incident was reported by a customer or partner affected by the incident
external-fraud-detectionThe incident was discovered through external fraud detection means (e.g., Common Point of Purchase reporting)
financial-auditThe incident was discovered during a financial audit and/or reconciliation process
hipsThe incident was discovered from host-based IDS or file integrity monitoring
incident-responseThe incident was discovered during the investigation of a separate incident
internal-fraud-detectionThe incident was discovered through internal fraud detection means
it-auditThe incident was discovered by an internal IT audit or scan
law-enforcementThe incident was reported by law enforcement
log-reviewThe incident was discovered during a log review process or by a Security Information and Event Management (SIEM) tool
monitoring-serviceThe incident was reported by a managed security event monitoring service
nidsThe incident was discovered by a network-based intrusion detection/prevention system
security-alarmThe incident was discovered by a physical security alarm
unknownIt is not known how this incident was discovered
unrelated-partyThe incident was reported by an unrelated party
userThe incident was reported by a user